[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: R41 in draft-ietf-v6ops-cpe-simple-security-07
On 28 jul 2009, at 19:22, Mohacsi Janos wrote:
Would it help to require a < 1024 port? On Unix-derived system you
have to be root to be able to send those, so random applications
wouldn't be able to do this without some serious tricking of the
user.
I don't think so. Most of the Windows users using their systems as
an Administrator. Administrator can do anything....
Does that mean an application can bind to a low port without the
system throwing up some kind of yes/no choice? (Not that that's
perfect, but it's something.)
Anyway the bots are preferring some exotic port numbers or
portnumber that is usually not firewalled: 80 and 443.
If a bot wants to receive incoming traffic on those ports it would
have to signal the CPE that it wants to be de-firewalled for those
ports.
(Not that malware spreads by listening on those ports, listening on
ports is _so_ 2003.)